November 2024
Title
SSA-331112 V1.0: Multiple Vulnerabilities in SINEC NMS Before V3.0 SP1
Published
Nov. 12, 2024, 1 a.m.
Summary
SINEC NMS before V3.0 SP1 is affected by multiple vulnerabilities. Siemens has released a new version for SINEC NMS and recommends to update to the latest version.
Title
SSA-000297 V1.0: Multiple SQLite Vulnerabilities in RUGGEDCOM CROSSBOW Station Access Controller Before V5.6
Published
Nov. 12, 2024, 1 a.m.
Summary
RUGGEDCOM CROSSBOW Station Access Controller (SAC) contains multiple vulnerabilities in the integrated SQLite component that could allow an attacker to execute arbitrary code or to create a denial of service condition. Siemens has released a new version for RUGGEDCOM CROSSBOW Station Access Controller (SAC) and recommends to update to the ...
Title
SSA-054046 V1.1 (Last Update: 2024-11-12): Unauthenticated Information Disclosure in Web Server of SIMATIC S7-1500 CPUs
Published
Nov. 12, 2024, 1 a.m.
Summary
Several SIMATIC S7-1500 CPU versions are affected by an authentication bypass vulnerability that could allow an unauthenticated remote attacker to gain knowledge about actual and configured maximum cycle times and communication load of the CPU. Siemens has released new versions for several affected products and recommends to update to the ...
Title
SSA-039007 V1.2 (Last Update: 2024-11-12): Heap-based Buffer Overflow Vulnerability in User Management Component (UMC)
Published
Nov. 12, 2024, 1 a.m.
Summary
Siemens User Management Component (UMC) is affected by a heap-based buffer overflow vulnerability which could allow an unauthenticated remote attacker arbitrary code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for ...
Title
SSA-454789 V1.0: Deserialization Vulnerability in TeleControl Server Basic V3.1
Published
Nov. 12, 2024, 1 a.m.
Summary
TeleControl Server Basic V3.1 contains a deserialization vulnerability that could allow an unauthenticated attacker to execute arbitrary code on the device. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Title
SSA-265688 V1.3 (Last Update: 2024-11-12): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1
Published
Nov. 12, 2024, 1 a.m.
Summary
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Title
SSA-230445 V1.0: Stored XSS Vulnerability in OZW Web Servers Before V5.2
Published
Nov. 12, 2024, 1 a.m.
Summary
OZW672 and OZW772 Web Server versions before V5.2 contain a stored cross-site scripting (XSS) vulnerability that could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker. Siemens has released new versions for the ...
Title
SSA-354112 V1.0: Multiple Vulnerabilities in SCALANCE M-800 Family Before V8.2
Published
Nov. 12, 2024, 1 a.m.
Summary
SCALANCE M-800 family before V8.2 is affected by multiple vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Title
SSA-398330 V2.0 (Last Update: 2024-11-12): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Published
Nov. 12, 2024, 1 a.m.
Summary
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). These GNU/Linux vulnerabilities have been externally identified. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not ...
Title
SSA-097435 V1.4 (Last Update: 2024-11-12): Usernames Disclosure Vulnerability in Mendix Runtime
Published
Nov. 12, 2024, 1 a.m.
Summary
Mendix Runtime contains an observable response discrepancy vulnerability when validating usernames during authentication. This could allow unauthenticated remote attackers to distinguish between valid and invalid usernames. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Title
SSA-364175 V1.3 (Last Update: 2024-11-12): Multiple Vulnerabilities in Palo Alto Networks Virtual NGFW on RUGGEDCOM APE1808 Devices Before V11.1.4-h1
Published
Nov. 12, 2024, 1 a.m.
Summary
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available. Customers are advised to consult and implement the workarounds ...
Title
SSA-616032 V1.0: Local Privilege Escalation Vulnerability in Spectrum Power 7 Before V24Q3
Published
Nov. 12, 2024, 1 a.m.
Summary
Spectrum Power 7 before V24Q3 contains several root-owned SUID binaries that could allow an authenticated local attacker to escalate privileges. Siemens has released a new version for Spectrum Power 7 and recommends to update to the latest version.
Title
SSA-064257 V1.0: Privilege Escalation Vulnerability in SIPORT Before V3.4.0
Published
Nov. 12, 2024, 1 a.m.
Summary
SIPORT before V3.4.0 contains a privilege escalation vulnerability which could allow a local attacker with an unprivileged account to override or modify the service executable and subsequently gain elevated privileges. Siemens has released a new version for SIPORT and recommends to update to the latest version.
Title
SSA-599968 V1.7 (Last Update: 2024-11-12): Denial-of-Service Vulnerability in Profinet Devices
Published
Nov. 12, 2024, 1 a.m.
Summary
A vulnerability in affected devices could allow an attacker to perform a denial-of-service attack if a large amount of Profinet Discovery and Configuration Protocol (DCP) reset packets is sent to the affected devices. Siemens has released new versions for several affected products and recommends to update to the latest versions. ...
October 2024
Title
SSA-333468 V1.0: Multiple Vulnerabilities in InterMesh Subscriber Devices
Published
Oct. 23, 2024, 2 a.m.
Summary
InterMesh Subscriber devices contain multiple vulnerabilities that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Title
SSA-438590 V1.0: Buffer Overflow Vulnerability in Siveillance Video Camera Drivers
Published
Oct. 10, 2024, 2 a.m.
Summary
Several camera device drivers in the Siveillance Video Device Pack contain a buffer overflow vulnerability that could be exploited under strict conditions. This could allow an attacker to execute code with the permissions of the Recording Server user. Siemens has released an update of the Device Pack recommends to apply ...
Title
SSA-097435 V1.3 (Last Update: 2024-10-10): Usernames Disclosure Vulnerability in Mendix Runtime
Published
Oct. 10, 2024, 2 a.m.
Summary
Mendix Runtime contains an observable response discrepancy vulnerability when validating usernames during authentication. This could allow unauthenticated remote attackers to distinguish between valid and invalid usernames. Siemens has released a new version for Mendix Runtime V8 and recommends to update to the latest version. Siemens is preparing further fix versions ...
Title
SSA-629254 V1.1 (Last Update: 2024-10-08): Remote Code Execution Vulnerability in SIMATIC SCADA and PCS 7 systems
Published
Oct. 8, 2024, 2 a.m.
Summary
The products listed below contain a remote code execution vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code with high privileges. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures ...
Title
SSA-626178 V1.0: Stack-Based Buffer Overflow Vulnerability in JT2Go Before V2406.0003
Published
Oct. 8, 2024, 2 a.m.
Summary
Siemens JT2Go is affected by a stack-based buffer overflow vulnerability that could be triggered when the application reads files in PDF format. If a user is tricked to open a malicious file with any of the affected products, this could lead the application to crash or potentially lead to arbitrary ...
Title
SSA-698820 V1.3 (Last Update: 2024-10-08): Multiple Vulnerabilities in Fortigate NGFW Before V7.4.4 on RUGGEDCOM APE1808 Devices
Published
Oct. 8, 2024, 2 a.m.
Summary
Fortinet has published information on vulnerabilities in FORTIOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version of Fortigate NGFW for RUGGEDCOM APE1808 and recommends to update to the latest version. Siemens recommends to consult and implement the workarounds provided in Fortinet’s upstream security notifications.
Title
SSA-711309 V2.1 (Last Update: 2024-10-08): Denial of Service Vulnerability in the OPC UA Implementations of SIMATIC Products
Published
Oct. 8, 2024, 2 a.m.
Summary
The OPC UA implementations (ANSI C and C++) as used in several SIMATIC products contain a denial of service vulnerability that could allow an unauthenticated remote attacker to create a denial of service condition by sending a specially crafted certificate. Siemens has released new versions for several affected products and ...
Title
SSA-783481 V1.3 (Last Update: 2024-10-08): Denial-of-Service Vulnerability in LOGO! 8 BM
Published
Oct. 8, 2024, 2 a.m.
Summary
A Denial-of-Service vulnerability has been identified in LOGO! 8 BM. This vulnerability could allow an attacker to crash a device, if a user is tricked into loading a malicious project file onto an affected device. The vulnerability is related to the hardware of the product. Siemens has released new hardware ...
Title
SSA-620288 V1.2 (Last Update: 2024-10-08): Multiple Vulnerabilities (NUCLEUS:13) in Capital Embedded AR Classic
Published
Oct. 8, 2024, 2 a.m.
Summary
Multiple vulnerabilities (also known as “NUCLEUS:13”) have be identified in the Nucleus RTOS (real-time operating system) and reported in the Siemens Security Advisory SSA-044112: https://cert-portal.siemens.com/productcert/html/ssa-044112.html. Capital Embedded AR Classic uses an affected version of the Nucleus software and inherently contains several of these vulnerabilities. Siemens has released a new version ...
Title
SSA-850560 V1.0: Use of 4-Digit PIN in SENTRON PAC3200 Devices
Published
Oct. 8, 2024, 2 a.m.
Summary
SENTRON PAC3200 only provide a 4-digit PIN to protect from administrative access via Modbus TCP interface. Attackers with access to the Modbus TCP interface could easily bypass this protection by brute-force attacks or by monitoring the Modbus cleartext communication. Siemens recommends specific countermeasures for products where fixes are not, or ...
Title
SSA-852501 V1.0: Multiple Memory Corruption Vulnerabilities in Simcenter Nastran Before 2406.5000
Published
Oct. 8, 2024, 2 a.m.
Summary
Simcenter Nastran contains multiple memory corruption vulnerabilities that could be triggered when the application reads files in BDF file formats. If a user is tricked to open a malicious file with any of the affected products, this could lead the application to crash or potentially lead to arbitrary code execution. ...

Last Updates

BOSCH PSIRT
15.01.2025
SIEMENS CERT
13.03.2025
US CERT
11.03.2025
US CERT (ICS)
13.03.2025

By Source

Archive

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds